Skip to main content
Pricing
Sign inRequest demo
MAS-CSO-FLOMUSTAll frameworksImplementation guide coming soon

Information Flows and Security Categories

Minimum Assessment Scope (MAS) · General Provider Responsibilities

Applies to: Providers
Who this applies to
Providers
Service class
All service classes
Force
MUST
Timeframe
No fixed timeframe

Reviewed implementation guidance for MAS-CSO-FLO is not published yet. The official source below remains complete and authoritative.

Expected evidence artifacts

  • A machine readable output containing all required data of the permitted connections between components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.
  • A human readable explanation of how the machine readable output is derived.
  • The code for the automated process used to generate the machine readable output.

Official FedRAMP source

Verbatim from FedRAMP/rules

Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.

Defined terms in this requirement

Operationalize this rule

Boundera turns FedRAMP 20x requirements like MAS-CSO-FLO into assigned evidence, remediation work, and validation workflows.

See it on your cloud

Notes

  • Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.

Change history

  • 2026-06-24Official launch of the FedRAMP Consolidated Rules for 2026.

Content provenance

Official requirement text is sourced from FedRAMP/rules . Boundera implementation guidance has not been fully reviewed for this item.